{"api_version":"1","generated_at":"2026-09-16T17:07:41+00:00","cve":"CVE-2026-76701","urls":{"html":"https://cve.report/CVE-2026-76701","api":"https://cve.report/api/cve/CVE-2026-76701.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76701","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76701"},"summary":{"title":"Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways","description":"A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.","state":"PUBLISHED","assigner":"hpe","published_at":"2026-09-15 20:17:54","updated_at":"2026-09-15 20:17:54"},"problem_types":[],"metrics":[{"version":"3.1","source":"security-alert@hpe.com","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US","name":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US","refsource":"security-alert@hpe.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76701","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76701","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Hewlett Packard Enterprise (HPE)","product":"EdgeConnect SD-WAN Gateways","version":"affected 9.7.0.0 9.7.0.0 semver","platforms":[]},{"source":"CNA","vendor":"Hewlett Packard Enterprise (HPE)","product":"EdgeConnect SD-WAN Gateways","version":"affected 9.6.0.0 9.6.3.1 semver","platforms":[]},{"source":"CNA","vendor":"Hewlett Packard Enterprise (HPE)","product":"EdgeConnect SD-WAN Gateways","version":"affected 9.5.0.0 9.5.8.1 semver","platforms":[]},{"source":"CNA","vendor":"Hewlett Packard Enterprise (HPE)","product":"EdgeConnect SD-WAN Gateways","version":"affected 9.4.0.0 9.4.8.2 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Internal security research (HPE Networking).","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"affected","product":"EdgeConnect SD-WAN Gateways","vendor":"Hewlett Packard Enterprise (HPE)","versions":[{"lessThanOrEqual":"9.7.0.0","status":"affected","version":"9.7.0.0","versionType":"semver"},{"lessThanOrEqual":"9.6.3.1","status":"affected","version":"9.6.0.0","versionType":"semver"},{"lessThanOrEqual":"9.5.8.1","status":"affected","version":"9.5.0.0","versionType":"semver"},{"lessThanOrEqual":"9.4.8.2","status":"affected","version":"9.4.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Internal security research (HPE Networking)."}],"descriptions":[{"lang":"en","value":"A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-09-15T19:23:58.418Z","orgId":"eb103674-0d28-4225-80f8-39fb86215de0","shortName":"hpe"},"references":[{"url":"https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US"}],"source":{"advisory":"HPESBNW05135","discovery":"INTERNAL"},"title":"Unauthenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Gateways","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"eb103674-0d28-4225-80f8-39fb86215de0","assignerShortName":"hpe","cveId":"CVE-2026-76701","datePublished":"2026-09-15T19:23:58.418Z","dateReserved":"2026-08-19T16:12:09.681Z","dateUpdated":"2026-09-15T19:23:58.418Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-15 20:17:54","lastModifiedDate":"2026-09-15 20:17:54","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"security-alert@hpe.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76701","Ordinal":"1","Title":"Unauthenticated Sensitive Information Disclosure in HPE Networki","CVE":"CVE-2026-76701","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76701","Ordinal":"1","NoteData":"A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD-WAN Gateways.","Type":"Description","Title":"Unauthenticated Sensitive Information Disclosure in HPE Networki"}]}}}